CRITICAL
9.3 CVE-2026-55674 Published 17 Aug 2026
Discourse Color Scheme Cookie XSS Vulnerability
Worried this affects one of your servers?
Discourse, an open-source discussion platform, is affected by an arbitrary HTML injection vulnerability that can lead to JavaScript execution.
Before versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id or dark_scheme_id cookie to inject arbitrary HTML into a Discourse page. The cookie value was rendered into a color scheme tag without escaping, allowing the attacker to break out of the attribute and inject a tag that bypassed Discourse's nonce-based Content Security Policy.
- Affected: versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
- Impact: arbitrary JavaScript execution in visitors' browsers
- Fixed: versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
Reference: CVE-2026-55674 on NVD
← Back to Security News